Cybersecurity researchers have revealed details of a new malware loader, dubbed QuirkyLoader, that is used to distribute a range of malicious payloads, ranging from infostealers to remote access trojans. The distribution is done via spam campaigns and the attacks have been ongoing since November 2024.

Some of the most prominent malware families distributed via QuirkyLoader include Agent Tesla, AsyncRAT, Formbook, Masslogger, Remcos RAT, Rhadamanthys Stealer, and Snake Keylogger.
QuirkyLoader malware
IBM X-Force, which analyzed the malware, said the attacks involve sending spam emails from legitimate email service providers as well as from a self-hosted email server. These emails contain a malicious file, which includes a DLL, an encrypted payload, and an actual executable file.
See also: Abuse of Generative AI platforms for Phishing campaigns
“The attacker uses DLL side-loading, a technique where launching the legitimate executable also loads the malicious DLL,” said security researcher Raymond Joseph Alfonso. “This DLL, in turn, loads, decrypts, and injects the final payload into the target process.”
This is achieved by using the process hollowing to insert the malware into one of three processes: AddInProcess32.exe, InstallUtil.exe or aspnet_wp.exe.
The DLL loader, according to IBM, has been used in limited campaigns in recent months, with two campaigns detected in July 2025 targeting Taiwan and Mexico.
See also: Phishing: Noodlophile malware distribution with new “bait”

The campaign targeting Taiwan is said to have targeted employees of Nusoft Taiwan, a network and internet security research firm based in New Taipei City, with the aim of infecting them with the Snake Keylogger, which is capable of stealing sensitive information from popular web browsers, keystrokes, and clipboard content.
The Mexico-related campaign, on the other hand, is estimated to be random, with infection chains distributing the Remcos RAT and AsyncRAT.
“The attacker consistently writes the DLL loader module in .NET languages and uses ahead-of-time (AOT) compilation,” Alfonso said. “This process compiles the code into native machine code before execution, making the final binary appear as if it were written in C or C++.”
QuirkyLoader is a typical example of malware that shows how attackers are constantly evolving their methods, combining detection evasion techniques with a seemingly legitimate execution chain. The use of DLL side-loading and process hollowing is not a new tactic, but the fact that the attacker leverages ahead-of-time compilation to make the code look “clean” (and difficult to analyze) increases the level of sophistication. This gives QuirkyLoader a more professional and durable appearance, allowing it to remain active for a longer period of time without being easily detected.
See also: Gemini exploit via Google Calendar to steal emails
The worrying thing is that QuirkyLoader is not limited to a single malware family. Instead, it acts as a “threat multiplier,” distributing malware that spans the entire spectrum: from infostealers that steal personal data and credentials, to remote access trojans that allow complete control over victim computers. This means that a single infection can have a cascade of consequences: loss of personal information, account compromise, theft of funds, or even complete control of corporate systems.

Recommended ways of protection
- Staff training – Phishing emails are the main means of infection. Constant updates and attack simulations significantly reduce the likelihood of success.
- Advanced email gateways – Filters that detect malicious attachments and suspicious headers can block a large portion of attacks.
- Application whitelisting – Restricting the execution of DLL or EXE files that do not have a certified origin reduces the risk of side-loading.
- Behavioral detection – Detecting suspicious behaviors, such as process hollowing, is more effective than simply scanning signatures.
- Zero Trust architecture – Restricting access to critical applications and data based on least privilege limits the consequences of a breach.
- Endpoint Detection & Response (EDR) – Tools that continuously monitor processes and allow for rapid isolation of infected systems.
The emergence of QuirkyLoader shows that attackers are becoming increasingly creative, which is why organizations must move beyond traditional defense and invest in multi-layered protection, combining technology, education, and preventative strategies.
